The Trusted Volumes hacker returns 1,122 ETH and keeps the $2 million reward

Featured in:
abcd

The hacker linked to the Trusted Volumes exploit returned 1,122 ETH to the protocol, closing part of a security incident that began with a multimillion-dollar exploit earlier this year.

The on-chain recovery is unusual because the attacker did not return everything. Instead, the wallet associated with the exploit sent back approximately $2 million worth of ETH, keeping another vast amount of what now appears to be a de facto reward. These types of results are known in DeFi, where projects sometimes negotiate with attackers after exploiting them rather than risk losing the full amount forever.

sadasda

Refunds matter because they reduce harm to the protocol and its users. But the structure of the settlement also shows how messy the DeFi security system remains. When sharp contracts fail, the market often relies on public pressure, wallet tracking and informal negotiations rather than a pure legal process.

Reference: Etherscan

TL;DR

  • The Trusted Volumes attacker returned 1,122 ETH to the protocol inventory.
  • The exploit originally cost approximately $5.9 million due to a vulnerability in sharp contracts.
  • It appears the attacker retained approximately $2 million as part of the reward settlement.

What happened to trusted volumes?

The exploit originates from a vulnerability in Trusted Volumes’ RFQ exchange proxy server. According to on-chain evidence, the May 7 attack caused the loss of approximately $5.9 million in assets by bypassing signature checks.

This is the type of vulnerability that can be particularly harmful in DeFi because it resides close to the protocol’s execution layer. If an exchange proxy accepts an invalid or improperly validated instruction, an attacker may be able to move funds in a way the system was never intended to allow.

The significant update is now the return of 1122 ETH from the attacker’s wallet to the protocol inventory. The primary source for this story is the wallet and transaction evidence on Etherscan, which shows the traffic recovery stage.

This does not necessarily mean that the minutes have been completed in their entirety. This means that a significant part of the funds used has been returned.

This distinction matters. A partial recovery may be better than nothing, but it still leaves users and the broader market wondering why the vulnerability existed, how quickly it was detected, and whether changes were made to the protocol to prevent a recurrence.

Why DeFi exploit settlements are still happening

Crypto has developed a strange pattern regarding major exploits.

In customary finance, theft usually leads to police reports, account freezes and lawsuits. In DeFi, the first reaction is often to track the public wallet. The attacker’s address is marked. Network analysts track the flow of funds. Protocol teams can post messages offering a reward in the event of a refund.

Sometimes attackers accept. Sometimes they disappear into mixers, bridges or exchange paths. Sometimes they return some and keep the rest.

That seems to be the shape of this case.

The reason for this is elementary: blockchains make funds apparent, but not always recoverable. If the attacker controls the private keys, the protocol cannot simply reverse the transaction. The best practical solution may be to offer a settlement before moving the funds forward.

It’s uncomfortable, but also realistic.

For users, the lesson is that code risk is not abstract. Even protocols with real activity can have a miniature implementation flaw that becomes a major loss. For developers, the lesson is even starker: signature validation, access control, proxy logic, and update paths require careful analysis because attackers only need one tender point.

Recovery helps, but does not remove the exploit

The 1,122 ETH return is clearly positive for Trusted Volumes, but should not be considered a full reset.

There was still an exploit. The funds were still removed. It appears the attacker was still holding a significant sum. The protocol still must demonstrate that the underlying problem has been resolved and that users can trust the system in the future.

This matters because DeFi trust is breakable after security incidents. Users can forgive a protocol that responds quickly, communicates clearly and recovers funds. They are less understanding when teams are vague, downplay an incident, or don’t explain what has changed.

The strongest next step for Trusted Volumes would be a clear postmortem: what failed, how the attacker used it, how the contract logic was fixed, and whether it had an impact on user balances.

By then, the market can recognize the recovery without pretending the episode is over.

It is also a useful reminder for the wider sector. DeFi security is not just about preventing hacks. It’s about incident response, transparency, on-chain monitoring and whether projects can regain enough trust when something goes wrong.

Trusted Volumes recovered some of the funds. The more challenging task is proving that the system is more secure than it was before the exploit.

This article is based on Etherscan wallet and transaction data.

This article was written by the News Desk and edited by Samuel Rae.

This report is based on information provided by Etherscan. On Etherscan

abcd
sadasda

Find us on

Latest articles

Related articles

See more articles

Will the US get CLARITY this week? Bitcoin’s fresh...

TRANSPARENCY is based on Trump's ethicsPolymarket suggests the CLARITY Act's chances of passing this year are just...

Allbridge Suspends Cross-Chain Bridge After $1.65M Exploit

Allbridge, the company behind the Allbridge Core cross-chain stablecoin bridge, said it had paused the protocol as...

South Korea investigated 40 cases of cryptocurrency manipulation in...

South Korea's financial authorities have investigated more than 40 cases of unfair trading, including market manipulation and...

Bitcoin liquidity clusters determine the direction of BTC prices...

Increased activity in the Bitcoin (BTC) futures markets is playing a dominant role in its short-term price...

MacOS malware hijacks Telegram sessions and attacks cryptocurrency wallets:...

Information-stealing malware on macOS can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security...

Saylor turns up the heat with “110 Reasons” why...

Executive Chairman of Strategy Michael Saylor took to social media on Sunday to detail his “110 Reasons”...